CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-12-03
Junior Member
 
Join Date: 2006-12-03
Posts: 3
Rep Power: 0
sabyno has an average reputation (10+)
Default R62 and incorrect handling syslog and ESP protocols

Hi everybody

I have one big problem.

I upgraded NGX R60 to R62. All seems OK and i got message upgrade successful, but just after upgrade I had problems with update SmartDefence. There was problem with SSL tunneling. I upgraded by the help of upgrade_import and upgrade_export utilites downloaded from checkpoint website. The upgrade was not successful

I tried upgrade in other way. I exported my policy from old version and I copied file object_5.0.C. Then I installed new version of SmartCenter and I imported file object_5.0.C and policy by cp merge command. Import was successful, so I was happy.

Now everything goes fine, but ...

I found two protocols, that checkpoint ignores and just forward. Protocols are ESP and syslog. Checkpoint doesn't log this protocols. When i want drop syslog for example by first rule checkpoint doesn't take no acction and it doesn't log anything, it just allow this protocol. I tried NAT over this protocol, but it doesn't work.

Is It bug??? Please help me. I don't know if R62 allows other protocols whithout any log or action

Thanks
Reply With Quote
  #2 (permalink)  
Old 2006-12-04
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 857
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: R62 and incorect handling syslog and ESP protocols

Implied rules?
Reply With Quote
  #3 (permalink)  
Old 2006-12-05
Junior Member
 
Join Date: 2006-12-03
Posts: 3
Rep Power: 0
sabyno has an average reputation (10+)
Default Re: R62 and incorect handling syslog and ESP protocols

There is not problem with impied rules I think. I log implied rules and i don't see syslog protocol. By the way in implied rules isn't rule containing syslog protocol.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 20:58.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0